## TL;DR
Supabase personal access credentials are created under your account settings (not the project settings), and the secret value is shown exactly once at creation. Generate it, copy it immediately into your secret store, and treat a lost value as gone: there is no reveal button, only revoke-and-recreate.

```text
supabase dashboard account tokens personal access token generate new token
```

## Use this when
- You need a credential for the Supabase Management API or CLI
- An agent needs to manage projects, not just query data
- You are following a guide that says "generate a new personal access credential"

## Not for this skill when
- You need the project's anon or service_role key (thats Project Settings \u2192 API, a different credential)
- An MCP/OAuth flow asks for a client id (thats an integration, not an account credential)
- You need the database password (thats Project Settings \u2192 Database)

## Steps

1. Go to the account-level settings, not the project. In the dashboard, open your avatar menu:

```text
Dashboard: avatar (top right) \u2192 Account \u2192 Access Credentials (or Personal Access Credentials)
```
Expected output: a list of existing credentials with names and creation dates, plus a "Generate new" button. If you are inside a project's Settings, you are in the wrong place.

2. Generate the credential with a descriptive name:

```text
Name it after its purpose, e.g. "mcp-management-read" or "ci-deploy"
```
Expected output: the dashboard shows the new credential value exactly once, usually with a copy button and a warning that it wont be shown again.

3. Copy it immediately into your secret manager or the tool config that needs it:

```bash
# paste it into your password manager / vault now, not later
```
Expected output: the value is stored somewhere durable. Navigating away or refreshing loses it permanently.

4. If you lost the value, revoke and re-create rather than hunting for it:

```text
Access Credentials \u2192 find the entry \u2192 Revoke, then Generate new
```
Expected output: the old value stops working and a fresh one is issued. There is no support flow that recovers a shown-once secret.

## Variant phrasings

### personal access credential shown once, how to see it again
You cant. Revoke and generate a new one; that is the designed flow.

### credential works in dashboard but not in CLI
The CLI may need the credential as an env var or login flag rather than pasted into a config file. Check the CLI's auth docs for the expected input.

## Why it happens
Account-level credentials authenticate YOU across all your projects, unlike project keys which are scoped to one database. Supabase shows the secret once because storing it server-side in recoverable form would defeat the purpose. People lose them because the generation UI looks like every other settings page, so they click through without copying.

## Edge cases
- These credentials inherit your account's permissions across projects; scope their use narrowly and rotate them.
- If your org uses SSO, personal access credentials may be disabled by policy; ask the org owner.
- Revoking a credential breaks every automation using it at once, so name credentials by purpose to know what will break.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_YapwwVqdn6knzSYhlAE-0Q
